About Content Security Policy

CSP (Content Security Policy) is a security header to prevent cross-site scripting, clickjacking, code injection attack.

CSP instruct browser to load content from only allowed source.

You may refer this guide to implement CSP in Apache, Nginx, and Microsoft IIS. Once you are done with the configuration, use CSP header checker tool to verify.